Both changes on main that postdate the deployed image affect startup or issuance
and both fail closed, so a mistake in either presents as a refusal rather than a
warning. That fact currently lives only in a State Hub message to the deployment
owner; messages age out of attention, and the repo is what the next session
reads, so operations.md is where it belongs.
Records what was actually checked rather than what is assumed: the deployed image
digest and the commit it was built from, that the live config's three browser
clients carry neither newly-rejected field, and that no deployed client declares
a tenant on a browser grant so the refusal is not yet reachable. Also states
plainly that neither change has been exercised against a running issuer, and that
the proof belongs to the attended window rather than to a session running against
production on its own.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016uV8zoCKpA1WRAxsKRYbdH
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1182213@bnt-lap001
Assistant-Session: 966597b9-ae61-46a4-8b9e-1594ab3ec4ad